Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Windows Tipps & SecurityGrafikkarte vor Überhitzung schützen: So geht’s(25.09.2026 um 08:00 Uhr)
••••••••••
Intelligence View
⚡ tsecurity.de Intelligence

How to Analyze SMTP Logs and Extract Email Traffic (PHP Script)

Working with mail servers? Then you already know one thing: 👉 SMTP logs are messy. When a client asks: “Can you send me only my email logs?” You’re stuck with a huge log file containing thousands of mixed records. In this post, I’ll sh…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Working with mail servers? Then you already know one thing:



👉 SMTP logs are messy.



When a client asks:



“Can you send me only my email logs?”



You’re stuck with a huge log file containing thousands of mixed records.



In this post, I’ll show you a simple but powerful way to extract a specific email’s traffic from SMTP logs using PHP.



🚨 The Problem



SMTP logs are not structured per email.



Instead, they look like this:



SMTP-IN 63EBA13D... 20.57..79 EHLO

SMTP-IN 63EBA13D... 20.57.
.79 MAIL FROM

SMTP-IN 63EBA13D... 20.57..79 RCPT TO:[email protected]

SMTP-IN 63EBA13D... 20.57.
.79 DATA



👉 Different emails are mixed together

👉 Same IP continues the flow

👉 Logs are split across multiple lines



So filtering by email alone is not enough.



💡 The Solution



Here’s the trick:



Find the line containing the target email

Extract the IP address from that line

Collect nearby lines with the same IP



This reconstructs the full SMTP flow.



⚙️ PHP Script




<?php

$logFile = __DIR__ . "/log/SMTP-Activity.log";
$outputFile = __DIR__ . "/log/output.log";

$targetMail = "[email protected]";
$range = 100;
$excludeIp = "185.86.*.14";

$lines = file($logFile, FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES);
$total = count($lines);

$out = fopen($outputFile, "w");

for ($i = 0; $i < $total; $i++) {

if (stripos($lines[$i], $targetMail) !== false) {

$parts = preg_split('/\t+/', $lines[$i]);
$ip = trim($parts[4] ?? '');

if (!$ip || $ip === $excludeIp) continue;

$start = max(0, $i - $range);
$end = min($total - 1, $i + $range);

fwrite($out, $lines[$i] . "\n");

for ($j = $start; $j <= $end; $j++) {

$p = preg_split('/\t+/', $lines[$j]);
$currentIp = trim($p[4] ?? '');

if ($currentIp === $excludeIp) continue;

if ($currentIp === $ip) {
fwrite($out, $lines[$j] . "\n");
}
}

fwrite($out, "\n\n");
}
}

fclose($out);

echo "Done!";
?>






📌 What You Get

Full SMTP flow for a specific email

Clean, client-ready log output

Faster debugging & analysis

🎯 Use Cases

Extract logs for a specific client

Debug email delivery issues

Detect brute-force login attempts

Analyze spam behavior

🔗 Full Tutorial (Detailed Explanation)



If you want a step-by-step explanation with real examples:



👉 https://sizinsayfaniz.com/blog2/Kurumsal-Mail-Sunuculari-Icin-Php-Log-Analizi.html



💻 GitHub Repository



👉 https://github.com/cahit2834/smtp-log-analiz-php



⚡ Final Thoughts



SMTP logs look chaotic, but with the right approach, you can extract meaningful insights easily.



If you're managing a mail server, this method will save you hours.



⭐ If this helped you, consider starring the repo!

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten How to Analyze SMTP Logs and Extract Email Traffic (PHP Script)

Thematisch verwandte Begriffe: Analyze, SMTP, Logs, Extract · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94418 | Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certifi…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag